To strengthen the company’s resilience in information security (InfoSec) and respective management mechanisms, we have integrated an approach from the corporate governance perspective by putting in place a comprehensive set of InfoSec policy, conducting regular cybersecurity drills, and organizing employee education and training to enhance overall InfoSec awareness. The ASEH Information Security Policy provides the highest level of management guidance to protect the confidentiality, integrity and availability of critical information assets, and to ensure compliance with relevant laws and regulations. With a robust InfoSec policy in place, ASEH is well positioned to boost customer trust, strengthen industry competitiveness, and maintain business continuity. We assess information security risks in accordance with regulatory requirements and business goals, and provide a status report to the senior management and the Board. The report offers a succinct overview of the InfoSec challenges and the current status, and forms the basis for the management and the Board to formulate additional guidelines, strategies and targets.
The Corporate Sustainability and Information Security Committee, comprised of board members, is chaired by Richard H.P. Chang, the current Vice Chairman of ASEH. The committee is responsible for overseeing the development of ASEH’s overall information security strategy and maturity benchmarking, planning and supervision of enterprise-wide cybersecurity risk management, monitoring the implementation of information security operations across subsidiaries, and coordinating the integration of internal and external technical resources and threat intelligence. These efforts aim to strengthen ASEH’s cybersecurity capabilities and reduce potential threats and risks. ASEH’s Chief Information Security Officer (CISO), a position created by the Corporate Sustainability and Information Security Committee is concurrently held by the Chief Administrative Officer and Head of Corporate Governance, assumes responsibility for the establishment of the information security management framework that includes regular reviews with all subsidiaries of ASEH and implementing incident response plans. The committee provides a status report to the Board of Directors in the last quarter of each fiscal year. In addition, the Executive Secretariat of the Chief Administrative Officer Office is responsible for promoting and executing information security-related work, and each subsidiary establishes its information security team to be responsible for implementing information security operations. We regularly hold quarterly meetings of the Information Security Team to report and discuss the progress of our information security work, and invite external experts to share information security trends and significant issues.
As our business continues to grow, the amount of information generated have also increased exponentially. Safeguarding the confidentiality, integrity and availability of information forms the cornerstone of ASEH’s information security management. Besides identifying internal and external information security risks and formulating countermeasures, we regularly implemented the NIST CSF maturity assessment in all facilities every year. Our cybersecurity policies are formulated to ensure the highest level of network and system protection and mitigation of impacts from any disruption. At the same time, education and training are actively conducted to enhance employee awareness on the importance of information security and prevent major data breaches. Building resilience through a robust information security management system is key to corporate sustainability and will greatly boost stakeholder satisfaction.
Developments in artificial intelligence (AI) technologies are transforming the pace of digitalization in the workplace. While we are driving broad-based AI adoption and integrating the technologies across the company, we do recognize the need to prioritize AI governance. ASEH’s AI governance is administered by the office of the Chief Administrative Officer, with responsibilities for coordinating with various company subsidiaries on the policy, framework and requirements. At the operating level, each department will integrate responsible AI practices relevant to their functions. We have published an ‘Artificial Intelligence Management Policy’ outlining AI governance principles and framework to guide AI adoption across the company. The policy covers the planning, development, deployment, use, monitoring and retirement throughout the AI adoption life cycle. It also outlines a structured approach to data privacy, information security, fairness, human feedback, transparency and interpretation, intellectual property, regulatory compliance, and ethical risk management. High-risk AI applications involving manipulation, exploitation of vulnerable groups, social scoring, and unauthorized biometric surveillance are explicitly prohibited.
To ensure the secure and responsible use of AI technologies, an AI tool as well as project application and approval process have been developed for our employees. Employees may only use authorized AI tools within the approved scope. AI applications involving personal data, confidential information, or other sensitive company data must comply with the classification and data protection policy, and undergo risk assessment and application reviews. Approved AI applications are continuously evaluated through model performance monitoring, model validation, drift analysis and AI risk assessments. Where necessary, models are adjusted or optimized to reduce the risks of bias, misuse or unintended outcomes. In addition, we have adopted the C.R.I.S.P.E prompting framework to standardize safe and effective AI use. Regular employee trainings are also scheduled to strengthen awareness of AI use, risks and governance.
At present, we are primarily using AI to support data analysis and improve operational efficiency, and not relying on it for autonomous decision-making. Human involvement will continue to play a key role in strategic decision-making as a safeguard to maintain human autonomy and accountability. AI technologies have been progressively adopted in areas including smart manufacturing, predictive maintenance, process optimization and generative AI applications. Key performance indicators such as reduction in work hours, productivity improvements, yield enhancement and other metrics are evaluated to determine the efficiency of AI adoption, while the results are used to drive continuous AI optimization. AI-related concerns have also been incorporated into the company's existing grievance, incident reporting and feedback mechanisms, enabling stakeholders to raise concerns or recommendations for review and appropriate follow-up. When procuring AI equipment and developing AI infrastructure, energy efficiency shall be key evaluation criteria. In addition, AI will be applied to continuously optimize our manufacturing process, equipment operation and resource allocation, improving operational efficiency while supporting sustainability development.
We conduct comprehensive cybersecurity maturity assessments at all our subsidiary companies to ensure the resilience and effectiveness of their cybersecurity programs. We have engaged PricewaterhouseCoopers (PwC) to conduct maturity assessments for the IT and OA operations of our global subsidiaries based on the NIST Cybersecurity Framework (CSF) 2.0. The framework covers 6 core functions: Govern, Identify, Protect, Detect, Respond, and Recover. In 2025, the company’s overall maturity level averaged 3.92, which is close to the Quantitatively Managed level of a structured, well-governed and mature cybersecurity management program.
Deloitte was engaged to conduct OT (operational technology) cybersecurity maturity assessments across our global manufacturing sites in accordance with the international standard IEC 62443. This encompasses a comprehensive evaluation of management practices and control systems for production and facility operations. Overall, our OT cybersecurity maturity is close to Level 3, demonstrating a well-established OT cybersecurity SOP and continuity in addressing security resilience of critical operational environments.
We engage third-party audit firms annually to conduct information security audits, system vulnerability scans, and penetration testing to ensure that its information systems and network environments comply with security implementation standards. These efforts help enforce information security policies and customer privacy protection measures, effectively preventing the leakage of trade secrets and customer data. Tools used include Nessus for vulnerability scanning, BitSight for security ratings, the Security Scorecard platform for analysis, and Red Team Assessments to evaluate system defense capabilities and incident response maturity. Additionally, the company provides monthly BitSight security rating reports to all sites for reference and continuous risk management improvement.
In addition to external audits, ASEH also conducts regular internal self-assessments of its Information Security Management System (ISMS) based on the NIST Cybersecurity Framework (CSF) and ISO 27001. These assessments evaluate the effectiveness of risk management, control measures, and incident response processes, and the results are reported to senior management and the Board of Directors. In the event of an unexpected cyberattack, the Information Security Management Task Force promptly convenes technical response meetings to analyze and review defense strategies, building a synchronized and comprehensive security network to respond to threats in real time.
In addition to managing operational risks from the perspective of corporate governance, we try to increase employees’ cybersecurity awareness and enhance organizational operational capabilities as part of our focuses in cybersecurity management. All employees at ASEH must receive PIP cybersecurity educational training, including cybersecurity policy, cybersecurity management framework, cybersecurity control measures, etc. In 2025, a total of 153,679 individuals completed 110,890 hours of training courses. Additionally, occasional social engineering email drills were conducted to enhance employees' awareness of social engineering attacks through emails. Additionally, we will gradually introduce systematic management mechanisms to incorporate participation in cybersecurity meeting, educational training, incident management, confidential file labeling, antivirus/software security, and other cybersecurity-related projects in a systematic manner. Moreover, KPI monitoring and audits are conducted, extending the scope of management, and reaching every employee and every endpoint device. This will be integrated with employees’ performance to reduce penalties and legal liabilities resulted from violations against cybersecurity regulations, as well as the impacts on business operations.
In 2025, no major information security incidents occurred at the company. To strengthen our cybersecurity response and protection capabilities, the company established a well-defined set of "IT Security Incident Reporting and Emergency Response Procedures". The procedure serves as a unified employee guideline that outlines detailed specifications, including incident classification, response team structure, severity level determination, reporting and handling procedures, incident monitoring and closure, follow-up investigations, corrective actions, and evidence collection. Cybersecurity incident drills are also conducted regularly to enhance employees' awareness and improve response efficiency.
The ASEH Information Security Management System further integrates cyber threat intelligence sharing and incident reporting, two core functions that enable real-time monitoring of internal and external threats, ensure timely reporting and resolution of incidents, and significantly enhance overall risk visibility and collaborative defense capabilities. With the increase in cybersecurity threats and the risks they pose to business operations, we have adopted a risk-based approach by securing cyber insurance coverage for the company. This added layer of protection allows us to respond swiftly to incidences and contain the impact of any cyberattacks, minimizing potential losses to the company operations, customers, supply chain partners and facilitating rapid business recovery.
To ensure the sustainable operations of important businesses and prevent interruption of critical information systems as a result of material cybersecurity incidents, we conduct an incident recovery drill every six months which lays out the organizational structure diagram, scope, duration, critical information systems, participating units, participating personnel and their assigned tasks, backup personnel for the drill, implementation steps and processes of the drill, required resources, data recovery from backup, risk management during the drill, post-drill review and improvement processes, among others. The purpose is to ensure the company can leverage disaster response capabilities and disaster recovery mechanisms to quickly restore operations to a normal or acceptable level for the business, achieving the goal of uninterrupted operations of critical information systems. The drill will continue to be implemented to provide maintenance, management, and training to ensure the effectiveness of the backup systems.
ASEH works closely with government agencies, local and international information security organizations including FIRST, Taiwan Computer Emergency Response Team/Coordination Center (TWCERT/CC), and High-tech Information Security Alliance. As a member of the SEMI Semiconductor Cybersecurity Committee, we are actively driving the industry’s adoption of SEMI E187 – Specification for Cybersecurity of Fab Equipment, a Taiwan-initiated security standard. Adopting the relevant infosec regulations, standards and industry intelligence allow us to integrate our internal management systems and expertise, to develop a comprehensive set of capabilities that will further strengthen our resilience.
At the same time, we are committed to meeting the expectations from our upstream and downstream supply chains and stakeholders on matters related to information security. ASEH’s strong and robust security defense leads to a tightly-secured smart manufacturing environment and increases the company’s competitive advantage as a sustainable enterprise.
Digital transformation and the exponential growth of data exchanged between organizations are increasing cybersecurity risks in the supply chain. At ASEH, we are consistently strengthening cybersecurity resilience across our upstream and downstream supply chains through systematic cybersecurity assessments. Our key suppliers follow a four-stage management approach: current situation assessment, guidance for improvement, confirmation of outcome, and repeated monitoring. The process includes questionnaires, on-site assessments, document reviews and technical evaluations to enhance the maturity of suppliers’ cybersecurity practices. Our deep focus in establishing a robust cybersecurity management framework has enabled the company to maintain a secure operation and resilient supply chain, while further enhancing the cybersecurity environment and standards of the semiconductor industry.
ASEH prioritizes cybersecurity issues, identifying internal and external risks, and developing and promoting various key response strategies. It has earned recognition with international cybersecurity certifications, including ISO 27001, ISO 22301, ISO 15408, ISO 21434, IEC 62443, GSMA, and others. Through continuous management of corporate operations and adherence to international information security standards, ASEH rigorously reviews and optimizes cybersecurity workflows and management measures, enhancing operational resilience. This comprehensive approach safeguards smart manufacturing security and sustains competitive advantages for the company.
To build a stable and robust foundation for the IT environment, ASE Kaohsiung, ASE Chungli, ASE Korea, SPIL, and USI Nantou continue to improve and implement cybersecurity risk management targeting critical information systems that are essential to the operation of crucial facilities.
ASE Kaohsiung, ASE Chungli, SPIL and USI Nantou have successively obtained the BCMS (business continuity management system) ISO22301 certification to strengthen crisis management and disaster response.
ASE Kaohsiung, ASE Chungli and ASE Singapore have been certified to EAL6, the highest level of security certification, creating a manufacturing environment and management system that comply with international standards for safe products and enhancing the safety management mechanisms for product transportation. We provide cybersecurity guarantees for manufacturing processes such as packaging and testing to offer better customer service.
ASE Kaohsiung is the first semiconductor assembly and testing facility in the world to receive the ISO/SAE 21434 international automotive network security standard certification with 100% compliance by being certified by TUV NORD of Germany.
ASE Kaohsiung passed the German TUV NORD’s professional evaluation and obtained the IEC 62443-2-1 certification, becoming the very first company to receive the certification in the semiconductor industry in Taiwan.
ASE Kaohsiung has passed the mobile communication security certification standard and obtained the GSMA certification. As a manufacturer, it completed a comprehensive audit of the production sites and processes to comply with the UICC production safety standard (GSMA SAS-UP).
USI Nantou, USI Zhangjiang, USI Kunshan, USI Mexico, and AFG Suzhou have all obtained the TISAX certification (Trusted Information Security Assessment Exchange), a standardized information security assessment framework for the automotive industry that enables secure data exchange and mutual recognition of assessment results.
ASEH approaches internal initiatives from a corporate governance perspective, establishing information security policies, conducting regular cybersecurity drills, providing cybersecurity education and awareness training for employees to enhance overall security awareness. It invites representatives from industry, government, and academia to share international cybersecurity developments regularly, increasing crisis responsiveness. Externally, ASEH actively participates in international cybersecurity organizations such as FIRST, TWCERT/CC Taiwan Cyber Security Alliance, and High-Tech Cyber Security Alliance. Through these communication channels, it shares the latest trends and action plans with industry peers and supply chain partners, elevating cybersecurity protection levels. Simultaneously, by aligning certification efforts with international standards, ASEH strives to mitigate cybersecurity threats, ensuring secure operations and fostering long-term, solid partnerships with customers and supply chain partners to provide more comprehensive and refined services.
Cybersecurity Policies, Organizations, and Goals
Established the Corporate Sustainability and Information Security Committee
Zero material cybersecurity incidents
Develop the Artificial Intelligence Management Policy
Formulated three cybersecurity goals for 2035
Convened four ASEH Information Security team meetings
Information Security Implementation and Safeguards
Implementation of one ASEH Information Security Management System
NIST CSF maturity assessment for 28 sites
OT cybersecurity maturity assessment for 28 sites
Conducted red team assessment at 5 sites
Provided monthly BitSight security rating reports
Conducted internal audits based on NIST CSF and ISO 27001 frameworks
Two cybersecurity incident drills
Providing cybersecurity educational training to 153,679 individuals
Accumulating 110,890 hours of cybersecurity educational training
Ongoing cybersecurity insurance coverage
Continue to Promote Supplier Cybersecurity Assessments
Cybersecurity Certification
ISO 27001 certified (ISMS): ASE Kaohsiung (TUV NORD), ASE Chungli (TUV NORD), ASE Korea(LRQA), SPIL(BSI), and USI Nantou(TNV)
ISO 22301 certified (BCMS): ASE Kaohsiung(BSI), ASE Chungli (TUV NORD), SPIL(BSI) and USI Nantou(DQS)
ASE Kaohsiung certified with IEC 62443-2-1(TUV NORD)
ISO 15408 EAL6 highest-level certification: ASE Kaohsiung(BSI), ASE Chungli(ANSSI), and ASE Singapore(BSI)
Obtained TISAX (ENX) certification for the USI Nantou, Zhangjiang, Kunshan, Mexico, and AFG Suzhou sites